Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

SonicWall

Vulnerabilities in SonicWall firewalls, Secure Mobile Access (SMA) appliances, and SSL-VPN gateways — perimeter gear that lands on CISA's Known Exploited Vulnerabilities catalog with unusual regularity and gets targeted by ransomware crews within days of disclosure.

17 CVEs6 articlesRSS
CVEs
CVE-2026-15409
[ CRITICAL ]CVSS 10.0EPSS 74.2%kev

SonicWall SMA1000 unauthenticated SSRF in Work Place portal

An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2026-15410
[ HIGH ]CVSS 7.2EPSS 76.3%kev

SonicWall SMA1000 post-authentication OS command injection

A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

SonicWall / SMA1000 Series (6210, 7210, 8200v)
CVE-2025-40602
[ MEDIUM ]CVSS 6.6EPSS 2.1%kev

SonicWall SMA1000 Missing Authorization Vulnerability

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

SonicWall / SMA1000 appliance
CVE-2023-44221
[ HIGH ]CVSS 7.2EPSS 74.9%kev

SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

SonicWall / SMA100 Appliances
CVE-2021-20035
[ MEDIUM ]CVSS 6.5EPSS 4.1%kev

SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

SonicWall / SMA100 Appliances
CVE-2024-53704
[ CRITICAL ]CVSS 9.8EPSS 95.1%kev

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

SonicWall / SonicOS
CVE-2025-23006
[ CRITICAL ]CVSS 9.8EPSS 23.4%kev

SonicWall SMA1000 Appliances Deserialization Vulnerability

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

SonicWall / SMA1000 Appliances
CVE-2024-40766
[ CRITICAL ]CVSS 9.8EPSS 18.2%kev

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

SonicWall / SonicOS
CVE-2019-7483
[ HIGH ]CVSS 7.5EPSS 4.0%kev

SonicWall SMA100 Directory Traversal Vulnerability

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

SonicWall / SMA100
CVE-2021-20028
[ CRITICAL ]CVSS 9.8EPSS 29.9%kev

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

SonicWall / Secure Remote Access (SRA)
CVE-2020-5135
[ CRITICAL ]CVSS 9.8EPSS 24.6%kev

SonicWall SonicOS Buffer Overflow Vulnerability

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

SonicWall / SonicOS
CVE-2021-20038
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

SonicWall / SMA 100 Appliances
CVE-2019-7481
[ HIGH ]CVSS 7.5EPSS 99.9%kev

SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

SonicWall / SMA100
CVE-2021-20016
[ CRITICAL ]CVSS 9.8EPSS 37.0%kev

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

SonicWall / SSLVPN SMA100
CVE-2021-20021
[ CRITICAL ]CVSS 9.8EPSS 83.4%kev

SonicWall Email Security Improper Privilege Management Vulnerability

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

SonicWall / SonicWall Email Security
CVE-2021-20022
[ HIGH ]CVSS 7.2EPSS 16.5%kev

SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

SonicWall / SonicWall Email Security
CVE-2021-20023
[ MEDIUM ]CVSS 4.9EPSS 50.2%kev

SonicWall Email Security Path Traversal Vulnerability

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

SonicWall / SonicWall Email Security
Articles
~/articles/2026-08-12-sonicwall-gms-critical-rce-discontinued
SonicWall GMS Patched for Critical Unauth RCE Flaws
sonicwall

SonicWall GMS Patched for Critical Unauth RCE Flaws

Critical unauthenticated RCE and data-read flaws patched in SonicWall GMS, which is end-of-life. If your GMS is internet-reachable, patch or isolate it now.

read →
~/articles/2026-08-10-sonicwall-sma1000-ransomware-gangs-cisa
CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000
sonicwall

CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000

CISA confirmed ransomware operators are actively exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in unpatched SonicWall SMA1000 appliances. Patch has been available since July 14.

read →
~/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22
Volexity ties SonicWall SMA1000 zero-days to UTA0533
sonicwall

Volexity ties SonicWall SMA1000 zero-days to UTA0533

Volexity attributes the SonicWall SMA1000 zero-day chain to UTA0533, first observed exploitation on June 22, four custom implants staged after.

read →
~/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail
SonicWall SMA1000: Volexity names UTA0533, IoC list out
sonicwall

SonicWall SMA1000: Volexity names UTA0533, IoC list out

Volexity attributes the SMA1000 pre-disclosure exploitation to a new actor, UTA0533, active since June 22 — and publishes the toolkit for defenders to hunt.

read →
~/articles/2026-07-15-rapid7-sma1000-mdr-writeup-mfa-seeds-dc-pivots
SonicWall SMA1000: what Rapid7 saw before disclosure
sonicwall

SonicWall SMA1000: what Rapid7 saw before disclosure

Rapid7 caught the SMA1000 zero-day exploitation before SonicWall's advisory. Attackers took credentials, MFA seeds, and pivoted to internal domain controllers.

read →
~/articles/2026-07-14-sonicwall-sma1000-cve-2026-15409-15410-kev-active-exploitation
SonicWall SMA1000 zero-days on CISA KEV: patch by July 17
sonicwall

SonicWall SMA1000 zero-days on CISA KEV: patch by July 17

Two SMA1000 flaws — a CVSS-10.0 unauthenticated SSRF and a post-auth code injection — hit CISA KEV today. Patch to 12.4.3-03453 or 12.5.0-02835 before July 17.

read →